nzcompare awards   Winners - Best Business Broadband Provider & People's Choice - Broadband 2025

Terms & Conditions

VAIA - Security Policy

Voyager AI Agent (VAIA) Security Policy

Introduction

VAIA is a product and service operated by Voyager Internet Ltd, referred to in this Security Policy as “Voyager”, “we”, “our”, or “us”.

VAIA is designed to help businesses automate communications, customer interactions, scheduling, and workflow management through artificial intelligence, voice technology, and integrated business systems.

Security is a core part of how we design, operate, and maintain the VAIA Platform. We are committed to protecting customer information and maintaining the confidentiality, integrity, and availability of the VAIA Platform and related services.

This Security Policy explains the security practices we use to help protect information processed by VAIA. It should be read together with the VAIA Privacy Policy and any applicable customer agreement.

We operate VAIA in accordance with applicable New Zealand laws, including the Privacy Act 2020.

Security Principles

VAIA is guided by the following security principles:

  • Protect customer information from unauthorised access, use, disclosure, alteration, loss, and misuse
  • Limit access to customer information to what is required for service delivery, support, security, and platform operation
  • Apply access controls based on least privilege
  • Use appropriate technical and organisational safeguards for the nature of the information we process
  • Monitor, maintain, and improve platform security over time
  • Respond promptly to security incidents
  • Support customer control over accounts, users, permissions, and connected integrations
  • Handle personal information in accordance with the VAIA Privacy Policy and the Privacy Act 2020

Data Protection

VAIA uses a combination of technical, operational, and administrative controls to help protect customer information.

These controls may include:

  • Secure authentication mechanisms
  • Role based access controls
  • Restricted administrative access
  • Encryption of information in transit and at rest where supported
  • Network security controls
  • Security logging and monitoring
  • Backups and recovery controls where applicable
  • Software updates and security patching
  • Access reviews
  • Staff awareness and internal security procedures

The specific controls used may vary depending on the VAIA feature, the type of information processed, and the systems or integrations involved.

Privacy Act 2020

Where VAIA processes personal information, Voyager handles that information in accordance with the Privacy Act 2020.

In particular, Voyager takes reasonable steps to protect personal information against loss, unauthorised access, use, modification, disclosure, and other misuse, consistent with Information Privacy Principle 5.

Where personal information is disclosed or made available to service providers located outside New Zealand, Voyager takes reasonable steps to ensure appropriate privacy and security protections are in place, consistent with Information Privacy Principle 12 and the VAIA Privacy Policy.

Infrastructure Security

VAIA is hosted using reputable cloud infrastructure providers and supporting technology services selected for reliability, scalability, and security.

Infrastructure security measures may include:

  • Secure cloud hosting environments
  • Network segmentation and access controls
  • Monitoring and alerting
  • Backup and recovery processes where applicable
  • Redundancy and resilience mechanisms
  • Change management controls

Restricted access to production systems is limited to authorised personnel who require access to perform their duties.

Account Security

Customers are responsible for maintaining the security of their own VAIA accounts, users, devices, credentials, and connected services.

We recommend that customers:

  • Use strong and unique passwords
  • Enable multi factor authentication where available
  • Limit access to authorised users only
  • Apply appropriate user permissions
  • Remove access promptly when staff leave or change roles
  • Regularly review connected integrations and permissions
  • Keep their own devices, networks, and systems secure
  • Report suspected unauthorised access promptly

Customers are responsible for activity carried out using their account credentials, unless that activity is caused by Voyager’s failure to meet its obligations.

Third Party Integrations

VAIA may connect with third party platforms and services chosen or authorised by customers.

These may include:

  • Calendar platforms
  • Customer relationship management systems
  • Communications platforms
  • Booking and reservation systems
  • Artificial intelligence services
  • Productivity and business applications
  • Other business systems selected by customers

VAIA only accesses connected services to provide customer requested functionality, operate the platform, support the customer, maintain security, or meet legal obligations.

Customers may revoke access to connected services at any time through the relevant third party provider or through the VAIA Platform where supported.

Third party services may have their own security, privacy, data retention, and access controls. Customers should review the terms and policies of any third party services they choose to connect to VAIA.

Artificial Intelligence and Data Handling

VAIA may use artificial intelligence technologies to provide automation, voice, communications, scheduling, transcription, summarisation, workflow, and related functionality.

Where AI services are used:

  • Only the information reasonably required to perform the requested function is processed
  • Customer information is handled in accordance with the VAIA Privacy Policy
  • Customer information is not used by Voyager for advertising purposes
  • Access to customer information is restricted to authorised systems and personnel where required for service delivery, support, security, or legal compliance
  • AI outputs may be generated based on customer instructions, customer data, connected systems, and platform configuration

AI generated outputs may not always be complete, accurate, or appropriate for every circumstance. Customers should review AI generated outputs before relying on them for business decisions, customer communications, legal matters, financial matters, or other important uses.

Google Services

Where VAIA integrates with Google services, Voyager’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

VAIA will only request access to Google information that is reasonably required to provide the relevant customer authorised functionality.

Vulnerability Management

Voyager regularly reviews and improves the security of the VAIA Platform.

Security activities may include:

  • Vulnerability assessments
  • Security monitoring
  • Software updates
  • Security patching
  • Infrastructure maintenance
  • Access reviews
  • Review of logs and alerts
  • Review of supplier and integration security where appropriate

Security improvements are implemented on an ongoing basis to support the reliability, resilience, and security of the VAIA Platform.

Incident Response

Voyager maintains processes for identifying, investigating, responding to, and managing security incidents.

In the event of a security incident affecting customer information, Voyager will take steps appropriate to the nature and severity of the incident. These may include:

  • Investigating the issue
  • Containing and mitigating potential impacts
  • Taking remediation action
  • Assessing whether personal information has been affected
  • Notifying affected customers where appropriate
  • Notifying the New Zealand Privacy Commissioner and affected individuals where required under the Privacy Act 2020
  • Reviewing the incident and improving controls where appropriate

A security incident may not always involve a privacy breach. Where an incident involves personal information, Voyager will assess whether it is a notifiable privacy breach under the Privacy Act 2020.

Customer Notification

If Voyager becomes aware of a security incident that materially affects a customer’s use of VAIA or the confidentiality, integrity, or availability of customer information, Voyager will take reasonable steps to notify the affected customer without undue delay.

The timing, content, and method of notification will depend on the circumstances, including the nature of the incident, whether investigation is ongoing, legal requirements, security considerations, and any contractual obligations.

Responsible Disclosure

If you believe you have discovered a security vulnerability affecting the VAIA Platform, we encourage responsible disclosure.

Please provide as much detail as possible, including:

  • A description of the issue
  • Steps to reproduce the issue
  • The potential impact
  • Supporting evidence where appropriate
  • Your contact details if you would like us to respond

Security reports should be submitted to:

[email protected]

We will make reasonable efforts to acknowledge and investigate legitimate security reports.

When testing or reporting a vulnerability, you must not:

  • Access, copy, modify, delete, or disclose customer data
  • Disrupt platform operations
  • Perform denial of service testing
  • Use social engineering
  • Send phishing communications
  • Attempt to gain persistence in any system
  • Exploit vulnerabilities beyond what is necessary to demonstrate the issue
  • Breach any applicable law

Unauthorised access to computer systems may be an offence under New Zealand law.

Data Retention and Deletion

VAIA retains customer information for as long as reasonably required to provide the services, meet legal or contractual obligations, resolve disputes, maintain security, prevent fraud or misuse, and operate the platform.

Where information is deleted, it may take a reasonable period for deletion to be reflected in backups, logs, audit records, and supporting systems.

Further information about retention and deletion of personal information is set out in the VAIA Privacy Policy.

Business Continuity and Availability

Voyager takes reasonable steps to maintain the availability and resilience of the VAIA Platform.

These steps may include:

  • Cloud infrastructure resilience
  • Monitoring and alerting
  • Backup processes where applicable
  • Incident response procedures
  • Recovery processes
  • Supplier and service dependency management

VAIA may be unavailable from time to time due to maintenance, updates, third party outages, telecommunications issues, security events, or circumstances outside Voyager’s reasonable control.

Customer Responsibilities

Security is a shared responsibility.

Voyager is responsible for the security of the VAIA Platform and the systems it controls.

Customers are responsible for:

  • Managing their own users and access permissions
  • Keeping login credentials secure
  • Maintaining the security of their own devices, networks, and systems
  • Reviewing AI generated outputs before using them
  • Ensuring their use of VAIA complies with applicable laws
  • Ensuring they have appropriate authority to connect third party systems
  • Configuring VAIA appropriately for their business needs
  • Promptly notifying Voyager of suspected security issues

Compliance

VAIA is operated in accordance with applicable New Zealand laws and recognised security practices.

Relevant laws and requirements may include:

  • Privacy Act 2020
  • Crimes Act 1961 provisions relating to unauthorised access to computer systems
  • Contractual obligations agreed with customers
  • Applicable requirements of third party platforms and service providers connected to VAIA

Where VAIA integrates with third party platforms, Voyager will comply with applicable security, privacy, and data handling requirements of those providers where those requirements apply to VAIA.

Changes to this Security Policy

Voyager may update this Security Policy from time to time to reflect changes to VAIA, our security practices, legal requirements, third party services, or operational needs.

The updated version will apply from the date it is published or otherwise notified, unless stated otherwise.

Contact

For general support or security queries, please contact:

Support Team: [email protected]

VAIA is a product of Voyager Internet Ltd.